1

拥有与 elasticsearch 5.6 一起使用的 elastalert docker 映像 ( https://hub.docker.com/r/ivankrizsan/elastalert/ ),更改为使用 ElasticSearch 6.1 (无索引) 的测试环境,现在得到

Creating Elastalert index in Elasticsearch...
Traceback (most recent call last):
  File "/usr/bin/elastalert-create-index", line 11, in <module>
    load_entry_point('elastalert', 'console_scripts', 'elastalert-create-index')()
  File "/opt/elastalert/elastalert/create_index.py", line 153, in main
    es.indices.put_mapping(index=index, doc_type='elastalert', body=es_mapping)
  File "build/bdist.linux-x86_64/egg/elasticsearch/client/utils.py", line 73, in _wrapped
  File "build/bdist.linux-x86_64/egg/elasticsearch/client/indices.py", line 282, in put_mapping
  File "build/bdist.linux-x86_64/egg/elasticsearch/transport.py", line 312, in perform_request
  File "build/bdist.linux-x86_64/egg/elasticsearch/connection/http_requests.py", line 90, in perform_request
  File "build/bdist.linux-x86_64/egg/elasticsearch/connection/base.py", line 125, in _raise_error
elasticsearch.exceptions.RequestError: TransportError(400, u'mapper_parsing_exception', u'No handler for type [string] declared on field [aggregate_id]')
4

2 回答 2

0

截至目前,elastalert 不支持开箱即用的 elasticsearch 6.0。这是 github 上的未解决问题:https ://github.com/Yelp/elastalert/issues/1399跟踪问题。https://github.com/Yelp/elastalert/pull/1426中也提到了一个漫游。

于 2018-01-02T16:48:15.657 回答
0

请升级到最新版本的 elastalert。我将 Elasticsearch 6.2 与 ElastAlert 0.1.29 一起使用,它们工作正常。

于 2018-02-28T16:33:34.600 回答